Virus Bulletin, July 1994
Total Page:16
File Type:pdf, Size:1020Kb
ISSN 0956-9979 JULY 1994 THE INTERNATIONAL PUBLICATION ON COMPUTER VIRUS PREVENTION, RECOGNITION AND REMOVAL Editor: Richard Ford CONTENTS Technical Editor: Fridrik Skulason Consulting Editor: Edward Wilding, EDITORIAL Network Security Management, UK Fire! 2 VIRUS PREVALENCE TABLE 3 NEWS Junkie Mail 3 VB 94 Conference on Track 3 Chill Out! 3 IN THIS ISSUE: IBM PC VIRUSES (UPDATE) 4 Scanner Update. The latest comparative review includes 27 anti-virus products. Find out which products FEATURE have kept up and which have fallen behind on pp.14-19. The Ludwig Collection 6 Viruses for Sale. Mark Ludwig has released a VIRUS ANALYSES CD-ROM containing thousands of viruses, including 1. Stealth.B: Invisible Fire 8 many new ones. What are the contents of The Collection, 2. Argyle: Viruses and the i386 10 and what are the implications for the industry? COMPARATIVE REVIEW Information Junkie. According to Reflex Inc, the latest The Review, Reviewed 12 virus to hit the streets is the new and dangerous Junkie VB Scanner Review: July 94 14 virus. An evaluation of the genuine threat to systems is given on p.3. PRODUCT REVIEW Norton on NetWare 20 REVIEW Virus: Prevention, Detection, Recovery 23 END NOTES & NEWS 24 VIRUS BULLETIN ©1994 Virus Bulletin Ltd, 21 The Quadrant, Abingdon, Oxfordshire, OX14 3YS, England. Tel. +44 (0)235 555139. /94/$0.00+2.50 No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form without the prior written permission of the publishers. 2 • VIRUS BULLETIN JULY 1994 EDITORIAL Fire! Last months article on the Pathogen virus, which criticised the way it had been publicised, elicited a squeal of discomfort from Dr Alan Solomon, who believes that the S&S International press release was far from wholly unnecessary (see VB, June 1994, p.3). Claiming that his actions were in the users interest, he insists that the alert was legitimate. However, whether or not this is the case, it seems likely that the publicity generated did more harm than good. When a new virus is first discovered, issuing a virus alert to product users is an attractive course of action, as it allows a new and unquantified threat to be dealt with in the quickest possible manner. If a user pays for protection from a company, he has some justification in expecting interim product updates if and when a new threat is discovered. Whether or not one should inform the popular press about a new virus is a much more difficult decision. At what level of threat does a virus alert become more than simple market manipulation? The new and One sample found in the wild? Ten? One hundred? When a new virus is discovered, there is rarely dangerous Blanc- any data available on how widespread it is. This was the case with Pathogen - the outbreak could mange virus, have been an isolated incident, or it could have been the tip of an iceberg. With little information on undetectable by all prevalence, press releases were put out by three different UK companies. known anti-virus Once a decision to send out a press release has been made, things become still more difficult, as software, has been control will pass from the technical department to the marketing or PR department. An honest discovered running description of a new virus out in the wild might read as follows: We at Acme Virus Detection Inc. have discovered a new virus named Blancmange at approximately 15 sites. The virus is not detected wild on UK ma- by the current version of our anti-virus software. Although there is no cause for alarm, users are chines urged to add the following driver file Such a report is factual, causes no panic and stands little or no chance of being published. However, thirty minutes after entering the PR office, the report might appear in a slightly different form: The new and dangerous Blancmange virus, undetectable by all known anti-virus software, has been discovered running wild on UK machines by Acme Virus Detection Inc. Currently, no other product except Acmes own AcmeScan can This puts an anti-virus software developer in a difficult position. Assuming he genuinely wants to alert the public to a potential threat, he will only get coverage by dramatising the situation. A calm, measured response is not news. Therefore, the spiced up release is distributed, and the marketing machine grinds away, the original motive for the warning long forgotten. There is no easy way out of this loop. S&S International is not the only company ever to obtain press coverage by releasing news of a new virus, and is certainly not the worst offender - it is in the company of several other major players in the industry. Secure Computing described Pathogen as spreading widely, while Reflex Inc (the USA vendors of Disknet) claims that the latest threat to security, the Junkie virus, is a new generation and of special concern. Such claims are counter- productive at best, and at worst leave the companies open to accusations of scare-mongering and market manipulation. When warning of a new virus, vendors should stick closely to the facts. One possible solution to this problem is that all companies take a measured response to new viruses. When the threat is believed to be small, nothing need be done until the next product update. When the threat is unknown, a factual warning should be issued to all product users. Finally, only when the threat is known to be large, with a significant number of sites infected, should a press campaign be launched. Until the extent of a problem is known, there is no justification for spreading alarm. The current situation is rather like that of the company fire officer who holds too many fire drills: the people in the building will eventually assume that the cry of Fire! does not require immediate action, merely a slow wander from the premises. The virus industry is putting itself in the same position by sending out misleading stories concerning the latest and greatest virus which is in the wild. How hard will it be to convince people when the threat is much larger? VIRUS BULLETIN ©1994 Virus Bulletin Ltd, 21 The Quadrant, Abingdon, Oxfordshire, OX14 3YS, England. Tel. +44 (0)235 555139. /94/$0.00+2.50 No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form without the prior written permission of the publishers. VIRUS BULLETIN JULY 1994 • 3 NEWS Virus Prevalence Table - May 1994 Junkie Mail Virus Incidents (%) Reports The latest virus to hit the headlines is Junkie, which, Form 21 40.4% according to a press release sent out by Reflex Inc, the Stoned 7 13.5% American reseller of Disknet, is of special concern. The JackRipper 3 5.8% press release (entitled Junkie - New Generation of Barrotes 2 3.9% Viruses Discovered: Nearly Undetectable, Dangerously Infectious) details how the virus was discovered in the wild, Cascade 2 3.9% in Ann Arbor, Michigan, USA. However, Reflex has had no Exebug.4 2 3.9% other reports of the virus in the wild since. NoInt 2 3.9% Analysis of the Junkie virus reveals that it is mildly poly- Spanish_Trojan 2 3.9% morphic, and capable of infecting both COM files and the V-Sign 2 3.9% Master Boot Sector of fixed disks. The virus contains no Anti-CMOS 1 1.9% trigger routine, and is described by Fridrik Skulason, author Dinamo 1 1.9% of F-Prot, as unremarkable. This description is entirely at odds with the semi-hysterical comments made by Reflex. DIR_II 1 1.9% Form.B 1 1.9% Commenting on the press release, Mr Frank Horowitz of Reflex Inc said, It was never our intention to cause panic. Michelangelo 1 1.9% We didnt mean to imply that Junkie would bring down Pathogen 1 1.9% every computer in the world, but to alert the user to the PS-Dropper 1 1.9% dangers of the new generation of viruses. If we succeed in Tequila 1 1.9% getting this message across to just one user, thats great! He went on further to say that such a press release could just as YMP 1 1.9% easily have been written about Pathogen or Chill, and was Total 52 100.0% meant to be a warning to both vendors and users. Horowitz stated that he had tried to point out that, despite the fact that this virus was no Michelangelo, the computer community had been lulled into a false sense of security ❚ Chill Out! VB ’94 Conference on Track A new virus has been found in nine files stored in the PBS Forum on ZiffNet. According to an Email message sent out The fourth annual VB Conference will be held in Jersey on by Katherine Prouty, ZiffNet Forums Manager, the virus, 8/9 September. Internationally recognised experts will speak known as Chill, was only on the forum between the dates of on topics ranging from Viruses in the Wild (Joe Wells), 3 June and 14 June. through The Computer Underground (Dr Alan Solomon), The Email goes on to explain that the virus did not originate to NetWare Security (Stephen Cobb). Delegates from in these files; versions of the programs downloaded before 3 every corner of the globe have registered: more than 25 June are absolutely fine. When asked how it was that the countries are now represented, including the first-ever files were uploaded uninfected, and later infected by the delegates from Hong Kong and Japan.